Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Trust Center / Cloud and Resilience

Licenses still expire. Applications still arrive. Inspections, enforcement, and revenue collection still have deadlines. Gov2Biz combines government-focused cloud infrastructure with defined backup, recovery, and disaster-preparedness practices to help agencies keep essential regulatory work moving.

01

Resilience is an operating discipline

Cloud hosting can provide a strong technical foundation, but availability does not come from a hosting decision alone. It depends on how the application is designed, how responsibilities are divided, how data is protected, how backups are managed, and how teams prepare for disruption.

Gov2Biz operates the platform in AWS GovCloud (US) and maintains practices for availability, backup, recovery planning, and disaster preparedness. This combination helps reduce the chance that a single failure becomes a prolonged interruption to agency work.

Our standard availability commitment is 99.5%. Other service levels are available for customers with different operational requirements. The applicable agreement defines how availability is measured, any exclusions, and the commitments that apply to that customer.

02

Keep the infrastructure and the data within a clear U.S. boundary

Gov2Biz customer data remains in the United States, including backups. The platform operates in AWS GovCloud (US), which provides isolated U.S. cloud regions designed for sensitive data and regulated workloads.

That boundary gives agency reviewers a direct answer to a central risk question. It also makes scope visible: if a customer adds its own integration or third-party service, that additional data flow should be evaluated as part of the complete implementation.

03

Know who is responsible for what

The phrase “hosted in AWS” can hide an important distinction. AWS protects the underlying infrastructure. It does not operate the Gov2Biz application or make security decisions for an agency.

AWS protects the cloud foundation

AWS is responsible for the facilities, hardware, networking, virtualization layer, and other infrastructure used to deliver its cloud services.

Gov2Biz protects and operates the platform

Gov2Biz is responsible for its applications and cloud environment, including configuration, access, monitoring, data handling, backup, recovery, vulnerability management, and service operations within our scope.

Each customer governs its side of the service

Customers retain responsibilities for their users, access decisions, endpoints, integrations, configurations, and use of the service, as defined by the implementation and applicable agreement.

Making that division explicit helps teams find gaps early instead of discovering them after launch.

04

Back up the data, then prepare to restore the service

A backup is valuable only if it supports a realistic recovery plan. Gov2Biz performs nightly backups and retains them on a standard 30-day first-in, first-out cycle. Customer data in backups remains in the United States.

Recovery planning considers two different questions: how quickly service should be restored and how much recent data could be affected by a qualifying disruption. The standard Gov2Biz recovery time objective is 12 hours, and the standard recovery point objective is 24 hours.

These objectives guide recovery planning. Binding commitments, measurement rules, exclusions, remedies, and customer-specific service levels are defined in the applicable agreement or SLA.

05

Practice the decisions before a disruption demands them

Recovery depends on people and decisions as much as technology. Gov2Biz conducts quarterly disaster-recovery tabletop exercises to rehearse responsibilities, test assumptions, identify gaps, and keep recovery procedures familiar to the people expected to use them.

Tabletop exercises do not predict every incident. They help the team enter an unexpected event with a practiced structure instead of beginning from a blank page.

06

Understand the cloud compliance boundary

AWS GovCloud supports government and regulated workloads, but its compliance programs do not automatically transfer to every application running within it. Gov2Biz does not represent AWS GovCloud hosting as automatic FedRAMP authorization or blanket compliance with every agency framework.

Your team should evaluate the complete system boundary, including the Gov2Biz application, agency responsibilities, data flows, integrations, and the evidence required for your specific use case.

Frequently asked questions

Gov2Biz is hosted in AWS GovCloud (US).

Yes. Gov2Biz customer data remains in the United States, including backups.

Gov2Biz performs nightly backups. Standard retention is 30 days on a first-in, first-out basis.

The standard recovery time objective is 12 hours, and the standard recovery point objective is 24 hours. Binding and customer-specific commitments are documented in the applicable agreement.

The standard Gov2Biz availability commitment is 99.5%. Other service levels are available for different customer requirements and are documented in the applicable agreement.

Gov2Biz conducts quarterly disaster-recovery tabletop exercises as part of its preparedness program.

No. AWS GovCloud provides the infrastructure foundation, but an application's authorization depends on the complete system scope, controls, assessment, and approval.

Make resilience part of the evaluation before it becomes part of the incident

Talk with Gov2Biz about your agency's hosting, data-residency, availability, recovery, and continuity requirements.